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18 June 1982 


MEMORANDUM FOR: Executive Director 
Deputy Director for Intelligence 
Deputy Director for Operations 
Deputy Director for Science and Technology 
General Counsel 
Inspector General 


Comptroller 
FROM: ,. 
Chief, Regulations Control Division 
SUBJECT: Proposed Revisions of Agency Information Security STAT 


Program, and Information Security Program 
Handbook (Jobs #27 and 28) 


FOR YOUR CONCURRENCE OR COMMENTS: 


Ts These proposed revisions of[ Jana [were initiated STABSTAT 


by the Office of Information Services to update Agency information security 
policy and procedures to conform with changes set forth in Executive 

Order 12356. These proposals are to be published simultaneously with 

the effective date of the order, 1 August 1982; please review them on 

an immediate basis. Because of expeditious handling, you will find some 
technical editorial inconsistencies in the handbook that will be corrected 
at the time of printing; i.e., changing "shall" to "will" and others. 


We therefore ask that your attention be focused primarily on substantive 
content. 


2: Please forward your concurrence and/or comments to the under- 
signed by 2 July 1982. Concurrence sheets are attached for your convenience. 


STAT 

Attachments: RNG SS 

A. Concurrence Sheets 

B. Proposed Revision of 

on Proposed Revision of ; Mi Mi F D [ATE 
cc: AO/DCI IHSA OF . 

SSA/DDA OEA Ol 

D/OIS OP OMS Pas" 160 (13) 

OIS/RMD IcS OSs 

OIS/IPD oc OTE eee ede — 

OIS/CRD ODP 
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HQ. INSTRUCTION SHEET 


REMOVE INSERT 


eer e eer [ EXPLANATION 


NOS. 


STAT , : ae | revised and STAT 
: 2/24/81 é updated to reflect 


policy set forth in 
Executive Order 12356. 


Arrows in the page margin show the locations of the changes 
described above. 


DISTRIBUTION: AB 
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INFORMATION AND RECORDS MANAGEMENT 
STAT Cc 
oan AGENCY INFORMATION SECURITY PROGRAM es 
synorszs| This regulation implements Executive 
~we- Order 12356 weeei 4 che Agency. Tt establishes the Agency 
program for classifying, downgrading, declassifying, marking, 
and safequarding national security information. 

a. INTRODUCTION 

(1) Except as provided in the Atomic Energy Act 

——tm of 1954, as amended, Executive Order 12356, National Security 
Information, provides the only basis for classifying 
information. 

(2) The National Security Council (NSC) may review 
all matters concerning the implementation of Executive 

ew Order 12356, and the NSC provides overall policy direction 
for the executive branch information security program. 

(3) The Administrator of General Services is 
responsible for implementing and monitoring the information 
security program established by the order. This responsibility 
is delegated to the Information Security Oversight Office (IS00O), 
which has a full-time director appointed by the Administrator 
subject to approval by the President. 

(4) No Change. 

[ex (5) The D/ISOO has the authority to convene and 
. chair interagency meetings to discuss matters pertaining to 


the information security program. 
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(6) The Attorney General, upon request by the head 
of an agency or D/ISOO, will render an interpretation of 
the order with respect to any question arising in the course 
of its administration. 

b. GENERAL ~ 

(1) No Change. 

(2) This regulation establishes, effective 
1 August 1982, the Agency information security program 
pursuant to Executive Order 12356 and related ISOO directives. 

(3) & (4) No Change. 

(5) A copy of this regulation and other regulations 
adopted to carry out this program will be submitted to the 
ISoo. The D/ISOO will require any regulation or guideline 
to be changed if it is not consistent with the order or 
implementing directives. Any such decision by the D/ISOO 
may be appealed to the NSC. The regulation or guideline 
will remain in effect until the appeal is decided. 

(6) Unclassified regulations that establish Agency 
information security policy will be published in the Federal 
Register to the extent that these pegdiseiens affect members 
of the public. 

(7) The D/ISOO has the authority to conduct on{site 
review of the Agency information security program and to 
require such reports, information, and other cooperation as 


necessary to fulfill His leeepenssii epee If such reports, 
/ or her / 
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inspection, or access to specific categories of classified 
information would pose an exceptional national security 
risk, the Director of Central Intelligencelmay deny access. 
f (BOT) 7 
The D/ISOO may appeal such denials to the NSC. The denial 
will remain in effect until the appeal is decided. ‘ 
Cus SANCTIONS 
(1) If the D/ISOO finds that a violation of 


E.O. 12356 or its implementing directives May have occurred, 


he or she sheti make a report to the DCI or the senior Agency 
/will/ 


: official designated in Seetion ef (1) below so that corrective 


/paragraph/ // 
steps |-i¢-appeepeiato, may be bared 
Sf : /, 1L£ appropriate,./ 
(2) Officials and employees of the Agency] and 


Agency contractors, licensees, and grantees Shall be subject 
/will/ 
to appropriate sanctions if they: 


(a) knowingly, willfully, or negligently disclose 
/K/ 


to unauthorized persons information properly classified under 


E.O. 12356 or predecessor orders| 
Swf, 
(b) knowingly and willfully classify or continue 
/K/ 


the classification of information in violation of the order 


. OY any implementing directive lox 


f xcf 
(c) lL scwingty and willfully violate any other 
/K/ 
provision of the order or implementing directive. 
(3) Sanctions may include reprimand, suspension 


without pay, removal, termination of classification authority, 


loss or denial of access to classified information, or other 


Sanctions in accordance with applicable law and Agency regulations. 
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(4) The DCI or the senior Agency official designated 


in Seekttieon ef (a) below shadi ensure that appropriate and prompt 
/paragraph/ // /will/ 


corrective action is taken whenever a violation under bs 
Section el (2) above occurs. Either stati ensure that the D/ISOO 
f/paragraph/ // /will/ 

Wye: is promptly notified whenever a Violation under Secédien el (2) 

/paragraph/ // 
(a) or (b) occurs. 
(Formerly c) d. POLICY AND PROCEDURES. No change. 
(Formerly d) es RESPONSIBILITIES 
(1) The Deputy Director for See eee ee 
/ (DDA) / 
i . the senior Agency official responsible for the direction an@ 


administration of the Agency information security program, 


which shett include an active oversight and security education 


/will/ 
program to Insure effective implementation oflthe Bped ees eeras 
/e/ /Section 5.3(a) of / /./ 
SvTote As the senior official for the information 


security program, khe-or-she is the person—in—the-Agency other 
/the DDA/ /sole alternate to the DCI for/ 
tha n~-theDirector_of—centeal_inteiligence whoa may—telegate 
/delegating/ // a // 
ae 


original Top Secret classification authority. 


(2) The Director of Information Services] ppalis 


/ (D/OIS),/ /, / 


responsible Box general management of the information security 


program. He—oe—she is the Agency focal point for contact 
/The D/OIS/ 
with the ISOO. On information security program matters, he-o 
/the D/OIS/ 
she~is the focal point fOr contact with the NSC and, through the 
// 
Office of General ueens ide Department of Justice. 
/ with / /t/ 
(3) 4 (5) No Change, 
/through/ 
(6) Delete. 


4. Reserved. 
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DATE 


TRANSMITTAL SLIP | 


TO: Ols (cep 


"opm NO. | BUILDING 
22. 


REMARKS: 


c/s ae Se WO? Gooha goat Y 


W/ 

A Lye y 
felors Kok ; 
°/ADMIN Mf ony O 
Ne/wret ae a 


“he co she” 6 The pte onl de 
“he s Webster j (s ie mn ibe ened sensel or 
when ae SEX f the eryen % un sped fed # a 


why ths paranoie bred! en ignoronce Ss werds 


<= 


FROM: 


ROOM NO. | ahi Armes Bide 


FORM NO. REPLACES FORM 36-8 
1Fep55| 241 WHICH MAY BE USED. 2 
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